feat: add combined docker+API service widgets for gitea/coolify/immich/n8n/umami/headscale
CI / Static checks (push) Successful in 35s
CI / Build and push image (push) Successful in 1m12s

One new `service` widget type (nested discriminated union on `service`)
rather than six, so a single config entry shows both docker container
health and a service-specific stat (repo count, project list, photo
count, workflow count, active users, users/nodes) - avoiding the
overhead of configuring a docker widget and a separate service widget
per container. All six collectors hit the service's container name +
internal port directly on falcon_network, the same container-to-
container pattern just proven out for Traefik's own API, avoiding
vpn-only/hairpin-NAT entirely.

Also adds the public/private config split that was scoped in the
original project plan but never built: lib/config/public.ts strips
apiToken/apiKey/password fields before the config reaches the browser
via SSR or the WS config topic - required before any widget could
carry a real secret. Verified via a throwaway secret field that it's
absent from both the SSR HTML and the WS config:update frame.

Endpoint shapes verified live against the running gitea/coolify/immich/
n8n/umami/headscale containers before committing (unauthenticated
requests correctly 401/200 on every target route; gitea's
X-Total-Count header confirmed present).
This commit is contained in:
2026-08-17 20:45:29 +02:00
parent aa657419ca
commit ffb70ecddf
18 changed files with 449 additions and 7 deletions
+8 -2
View File
@@ -3,6 +3,7 @@ import { WebSocket, WebSocketServer } from "ws";
import { collectorScheduler } from "@/lib/collectors/scheduler";
import { configStore, type ConfigError } from "@/lib/config/loader";
import { effectiveConfigStore } from "@/lib/config/effective";
import { toPublicConfig } from "@/lib/config/public";
import type { Config } from "@/lib/config/schema";
import type { WidgetResult } from "@/lib/types/widget-result";
@@ -49,7 +50,7 @@ export function attachWebSocketServer(httpServer: HttpServer): WebSocketServer {
try {
const config = effectiveConfigStore.get();
send(socket, { topic: "config", type: "config:update", ts: Date.now(), data: config });
send(socket, { topic: "config", type: "config:update", ts: Date.now(), data: toPublicConfig(config) });
} catch {
// no valid config loaded yet; client keeps its SSR-seeded config until one arrives
}
@@ -80,7 +81,12 @@ export function attachWebSocketServer(httpServer: HttpServer): WebSocketServer {
});
effectiveConfigStore.onUpdate((config) => {
const envelope: Envelope = { topic: "config", type: "config:update", ts: Date.now(), data: config };
const envelope: Envelope = {
topic: "config",
type: "config:update",
ts: Date.now(),
data: toPublicConfig(config),
};
for (const socket of allSockets) send(socket, envelope);
});